10 min read
Anthropic Found a Fourth Claude Breach and Called In METR
Anthropic disclosed a fourth Claude incident on Sept 9 and brought in independent evaluator METR to check its…
The Lab · Written in the open · Tagged Security
Working notes from the studio. The tools I build, the workflows I keep, the mistakes I paid for.
12 entries · latest 2026-09-11
Latest entry
Anthropic's September threat report details nine months of real Claude misuse, from drone swarms to stolen API keys used as loot.
Read the entryAll entries · Security
10 min read
Anthropic disclosed a fourth Claude incident on Sept 9 and brought in independent evaluator METR to check its…
9 min read
Every RAXXO tool, free or paid, passes the same five-check security review before launch. Here is the checklist…
15 min read
GPT-6 Astra is the first model OpenAI rates Critical for cyber. It also monitors worse than the model…
9 min read
A missing noindex tag let shared Claude conversations and Artifacts turn up in Google and Bing search results…
9 min read
Anthropic shipped Claude Security in beta, a multi-agent scanner that turns vulnerability findings into reviewed patches inside Claude…
8 min read
Claude Security left its launch behind with scheduled scans, directory targeting, and CSV or Markdown exports.
8 min read
Claude Security entered public beta on May 2026, scanning repos and explaining vulnerabilities for Claude Enterprise customers only
8 min read
Shopify now requires expiring offline access tokens for all new public apps as of April 1
8 min read
Attacker opened 475+ malicious PRs across GitHub in 26 hours using AI-generated payloads
10 min read
Project Glasswing uses Claude Mythos Preview to find zero-days in critical infrastructure. 12 partners, 100M USD in credits,…
11 min read
Three versions of anti-cheat for a CSS centering game with 3,000+ attempts. HMAC tokens, pattern analysis, and HTTP…